ZeroHour

CVE-2022-25647

CVSS 3.1
7.5 high
EPSS
12%p96
Published
()
Modified
Description

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

Vendors
googledebiannetapporacle
Products
gson, debian linux, active iq unified manager, financial services crime and compliance management studio, graalvm, retail order broker
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news